i vmnet8 port 53 16:11:16.476533 IP 192.168.63.1

Transcription

i vmnet8 port 53 16:11:16.476533 IP 192.168.63.1
25/11/13 15:59:28 5830 # tcpdump -i vmnet8 port 53
16:11:16.476533 IP 192.168.63.1.34801 > 192.168.63.141.domain: 24907+ A? dns2.rs.tp. (28)
16:11:16.476919 IP 192.168.63.1.33941 > 192.168.63.141.domain: 62816+ PTR?
141.63.168.192.in-addr.arpa. (45)
16:11:16.477059 IP 192.168.63.141.domain > 192.168.63.1.34801: 24907* 1/2/2 A 192.168.63.141
(111)
16:11:16.478180 IP 192.168.63.141.domain > 192.168.63.1.33941: 62816 NXDomain 0/1/0 (122)
16:11:16.478382 IP 192.168.63.1.47183 > 192.168.63.141.domain: 11963+ PTR? 1.63.168.192.inaddr.arpa. (43)
16:11:16.478741 IP 192.168.63.141.25713 > blackhole-2.iana.org.domain: 49802% [1au] PTR?
1.63.168.192.in-addr.arpa. (54)
-16:11:16.489883 IP blackhole-2.iana.org.domain > 192.168.63.141.25713: 49802 NXDomain*0/1/1 (131)
16:11:16.490627 IP 192.168.63.141.domain > 192.168.63.1.47183: 11963 NXDomain 0/1/0 (120)
16:11:16.490796 IP 192.168.63.1.54844 > 192.168.63.141.domain: 53372+ PTR? 42.48.175.192.inaddr.arpa. (44)
16:11:16.491696 IP 192.168.63.141.33782 > z.arin.net.domain: 37481% [1au] PTR?
42.48.175.192.in-addr.arpa. (55)
16:11:16.607618 IP z.arin.net.domain > 192.168.63.141.33782: 37481- 0/7/1 (427)
16:11:16.610216 IP 192.168.63.141.61974 > a.gtld-servers.net.domain: 36325% [1au] A? ns.dnsoarc.net. (44)
16:11:16.610834 IP 192.168.63.141.49255 > a.gtld-servers.net.domain: 33332% [1au] AAAA?
ns.dns-oarc.net. (44)
16:11:16.612109 IP 192.168.63.141.8428 > a.gtld-servers.net.domain: 63531% [1au] A?
sec2.authdns.ripe.net. (50)
16:11:16.612775 IP 192.168.63.141.48671 > a.gtld-servers.net.domain: 41250% [1au] AAAA?
sec2.authdns.ripe.net. (50)
16:11:16.613450 IP 192.168.63.141.54367 > a.gtld-servers.net.domain: 47603% [1au] A?
iskra.ottix.net. (44)
16:11:16.614092 IP 192.168.63.141.15713 > a.gtld-servers.net.domain: 26335% [1au] AAAA?
iskra.ottix.net. (44)
16:11:16.615088 IP 192.168.63.141.34810 > a.root-servers.net.domain: 3360% [1au] A?
authns2.net.umd.edu. (48)
16:11:16.615665 IP 192.168.63.141.11471 > a.root-servers.net.domain: 8493% [1au] AAAA?
authns2.net.umd.edu. (48)
16:11:16.616546 IP 192.168.63.141.47977 > d0.org.afilias-nst.org.domain: 43915% [1au] A? snspb.isc.org. (43)
16:11:16.617324 IP 192.168.63.141.40202 > d0.org.afilias-nst.org.domain: 23760% [1au] AAAA?
sns-pb.isc.org. (43)
16:11:16.617922 IP 192.168.63.141.20510 > a.root-servers.net.domain: 24251% [1au] NS? . (28)
16:11:16.634959 IP a.root-servers.net.domain > 192.168.63.141.34810: 3360- 0/8/8 (490)
16:11:16.636312 IP 192.168.63.141.46798 > a.gtld-servers.net.domain: 52533% [1au] A?
authns2.net.umd.edu. (48)
16:11:16.644024 IP a.root-servers.net.domain > 192.168.63.141.11471: 8493- 0/8/8 (490)
16:11:16.644063 IP a.root-servers.net.domain > 192.168.63.141.20510: 24251*- 14/0/23 NS
e.root-servers.net., NS a.root-servers.net., NS l.root-servers.net., NS h.root-servers.net., NS b.rootservers.net., NS k.root-servers.net., NS f.root-servers.net., NS c.root-servers.net., NS d.rootservers.net., NS j.root-servers.net., NS i.root-servers.net., NS g.root-servers.net., NS m.rootservers.net., RRSIG (857)
16:11:16.645316 IP 192.168.63.141.27128 > a.gtld-servers.net.domain: 54211% [1au] AAAA?
authns2.net.umd.edu. (48)
16:11:16.708501 IP d0.org.afilias-nst.org.domain > 192.168.63.141.40202: 23760- 0/7/7 (514)
16:11:16.710442 IP 192.168.63.141.2060 > sfba.sns-pb.isc.org.domain: 16328% [1au] AAAA? snspb.isc.org. (43)
16:11:16.711319 IP 192.168.63.141.20990 > c.root-servers.net.domain: 49153% [1au] A?
ns.isc.afilias-nst.info. (52)
16:11:16.711912 IP 192.168.63.141.5659 > c.root-servers.net.domain: 12666% [1au] AAAA?
ns.isc.afilias-nst.info. (52)
16:11:16.717523 IP d0.org.afilias-nst.org.domain > 192.168.63.141.47977: 43915- 0/7/7 (514)
16:11:16.718769 IP 192.168.63.141.37582 > sfba.sns-pb.isc.org.domain: 784% [1au] A? snspb.isc.org. (43)
16:11:16.727967 IP a.gtld-servers.net.domain > 192.168.63.141.61974: 36325- 0/4/2 (301)
16:11:16.729190 IP 192.168.63.141.25065 > ns.dns-oarc.net.domain: 50061% [1au] A? ns.dnsoarc.net. (44)
16:11:16.734668 IP c.root-servers.net.domain > 192.168.63.141.20990: 49153- 0/9/13 (686)
16:11:17.282432 IP 192.168.63.1.47592 > 192.168.63.141.domain: 28437+ PTR? 63.0.212.199.inaddr.arpa. (43)
16:11:17.284210 IP 192.168.63.141.60518 > c.in-addr-servers.arpa.domain: 45507% [1au] PTR?
63.0.212.199.in-addr.arpa. (54)
16:11:17.460105 IP c.in-addr-servers.arpa.domain > 192.168.63.141.60518: 45507- 0/10/1 (398)
16:11:17.461300 IP 192.168.63.141.20791 > x.arin.net.domain: 55245% [1au] PTR?
63.0.212.199.in-addr.arpa. (54)
16:11:18.279207 IP 192.168.63.1.58959 > 192.168.63.141.domain: 20908+ PTR? 30.6.5.192.inaddr.arpa. (41)
16:11:18.280090 IP 192.168.63.141.29240 > w.arin.net.domain: 30990% [1au] PTR? 30.6.5.192.inaddr.arpa. (52)
16:11:18.688926 IP 192.168.63.1.48862 > 192.168.63.141.domain: 63244+ PTR? 4.0.41.198.inaddr.arpa. (41)
16:11:18.689783 IP 192.168.63.141.20061 > d.in-addr-servers.arpa.domain: 685% [1au] PTR?
4.0.41.198.in-addr.arpa. (52)
16:11:18.908304 IP d.in-addr-servers.arpa.domain > 192.168.63.141.20061: 685- 0/10/1 (396)
16:11:18.909505 IP 192.168.63.141.58272 > u.arin.net.domain: 50883% [1au] PTR? 4.0.41.198.inaddr.arpa. (52)
16:11:18.923346 IP u.arin.net.domain > 192.168.63.141.58272: 50883- 0/5/1 (337)
16:11:18.925659 IP 192.168.63.141.35933 > d.gtld-servers.net.domain: 41451% [1au] A?
a1.verisigndns.com. (47)
16:11:19.271231 IP 192.168.63.1.52035 > 192.168.63.141.domain: 36812+ PTR? 1.57.19.199.inaddr.arpa. (42)
16:11:19.272134 IP 192.168.63.141.8121 > w.arin.net.domain: 36724% [1au] PTR? 1.57.19.199.inaddr.arpa. (53)
16:11:19.480893 IP 192.168.63.1.36158 > 192.168.63.141.domain: 32341+ PTR? 3.64.20.149.inaddr.arpa. (42)
16:11:19.481911 IP 192.168.63.141.16885 > b.in-addr-servers.arpa.domain: 32083% [1au] PTR?
3.64.20.149.in-addr.arpa. (53)
16:11:19.505136 IP b.in-addr-servers.arpa.domain > 192.168.63.141.16885: 32083- 0/10/1 (397)
16:11:19.506332 IP 192.168.63.141.17305 > t.arin.net.domain: 43920% [1au] PTR? 3.64.20.149.inaddr.arpa. (53)
16:11:19.614556 IP t.arin.net.domain > 192.168.63.141.17305: 43920- 0/6/1 (382)
16:11:19.617201 IP 192.168.63.141.28534 > ams.sns-pb.isc.org.domain: 57434% [1au] PTR?
3.64.20.149.in-addr.arpa. (53)
16:11:19.682761 IP ams.sns-pb.isc.org.domain > 192.168.63.141.28534: 57434*- 2/4/13 PTR
sfba.sns-pb.isc.org., RRSIG (1472)
16:11:19.684208 IP 192.168.63.141.54069 > ord.sns-pb.isc.org.domain: 5674% [1au] DNSKEY?
64.20.149.in-addr.arpa. (51)
16:11:19.790544 IP ord.sns-pb.isc.org.domain > 192.168.63.141.54069: 5674*- 4/0/1 DNSKEY,
DNSKEY, RRSIG, RRSIG (970)
16:11:19.990428 IP 192.168.63.1.42497 > 192.168.63.141.domain: 48516+ PTR? 12.4.33.192.inaddr.arpa. (42)
16:11:20.384817 IP 192.168.63.1.43438 > 192.168.63.141.domain: 12050+ PTR? 65.58.20.149.inaddr.arpa. (43)
16:11:20.385662 IP 192.168.63.141.29331 > ams.sns-pb.isc.org.domain: 49508% [1au] PTR?
65.58.20.149.in-addr.arpa. (54)
16:11:20.402993 IP ams.sns-pb.isc.org.domain > 192.168.63.141.29331: 49508- 0/4/5 (712)
16:11:20.404190 IP 192.168.63.141.49002 > sns-pb.isc.org.domain: 35174% [1au] PTR?
65.58.20.149.in-addr.arpa. (54)
16:11:20.419876 IP sns-pb.isc.org.domain > 192.168.63.141.49002: 35174*- 1/3/7 PTR ns.dnsoarc.net. (719)
16:11:20.440838 IP 192.168.63.1.60041 > 192.168.63.141.domain: 24550+ PTR?
10.169.216.196.in-addr.arpa. (45)
16:11:20.441542 IP 192.168.63.141.17678 > f.in-addr-servers.arpa.domain: 33608% [1au] PTR?
10.169.216.196.in-addr.arpa. (56)
16:11:20.456579 IP f.in-addr-servers.arpa.domain > 192.168.63.141.17678: 33608- 0/10/1 (486)
16:11:21.144924 IP 192.168.63.1.34997 > 192.168.63.141.domain: 47557+ PTR? 63.0.71.199.inaddr.arpa. (42)
16:11:21.145732 IP 192.168.63.141.59538 > u.arin.net.domain: 39810% [1au] PTR? 63.0.71.199.inaddr.arpa. (53)
16:11:21.209701 IP 192.168.63.1.49871 > 192.168.63.141.domain: 7223+ PTR? 2.71.52.72.inaddr.arpa. (41)
16:11:21.210443 IP 192.168.63.141.57890 > b.in-addr-servers.arpa.domain: 63906% [1au] PTR?
2.71.52.72.in-addr.arpa. (52)
16:11:21.925449 IP 192.168.63.1.41243 > 192.168.63.141.domain: 57427+ PTR? 53.60.10.200.inaddr.arpa. (43)
16:11:21.926444 IP 192.168.63.141.9192 > f.in-addr-servers.arpa.domain: 10975% [1au] PTR?
53.60.10.200.in-addr.arpa. (54)
16:11:22.840416 IP 192.168.63.1.36425 > 192.168.63.141.domain: 31567+ PTR? 50.216.61.204.inaddr.arpa. (44)
16:11:22.841301 IP 192.168.63.141.25005 > f.in-addr-servers.arpa.domain: 1749% [1au] PTR?
50.216.61.204.in-addr.arpa. (55)
16:11:22.943512 IP 192.168.63.1.46758 > 192.168.63.141.domain: 18725+ PTR? 30.80.31.192.inaddr.arpa. (43)
16:11:22.944356 IP 192.168.63.141.17051 > u.arin.net.domain: 62752% [1au] PTR?
30.80.31.192.in-addr.arpa. (54)
16:11:23.088092 IP 192.168.63.1.49125 > 192.168.63.141.domain: 49571+ PTR?
183.183.253.199.in-addr.arpa. (46)
16:11:23.088925 IP 192.168.63.141.37279 > u.arin.net.domain: 47557% [1au] PTR?
183.183.253.199.in-addr.arpa. (57)
16:11:23.102497 IP u.arin.net.domain > 192.168.63.141.37279: 47557*- 1/4/1 PTR b.in-addrservers.arpa. (179)
16:11:23.103868 IP 192.168.63.141.64065 > u.arin.net.domain: 29553% [1au] DS? 253.199.inaddr.arpa. (49)
16:11:23.137113 IP 192.168.63.1.52941 > 192.168.63.141.domain: 63906+ PTR?
63.249.253.199.in-addr.arpa. (45)
16:11:23.138111 IP 192.168.63.141.1486 > u.arin.net.domain: 1025% [1au] PTR?
63.249.253.199.in-addr.arpa. (56)
16:11:23.191691 IP 192.168.63.1.56199 > 192.168.63.141.domain: 8478+ PTR? 30.1.6.199.inaddr.arpa. (41)
16:11:23.193247 IP 192.168.63.141.53443 > u.arin.net.domain: 8416% [1au] PTR? 30.1.6.199.inaddr.arpa. (52)
16:11:23.320442 IP 192.168.63.1.36698 > 192.168.63.141.domain: 34006+ PTR? 30.0.6.199.inaddr.arpa. (41)
16:11:23.321263 IP 192.168.63.141.63138 > u.arin.net.domain: 57415% [1au] PTR? 30.0.6.199.inaddr.arpa. (52)
16:11:24.335249 IP 192.168.63.1.49691 > 192.168.63.141.domain: 36171+ PTR? 1.4.5.192.inaddr.arpa. (40)
16:11:24.335516 IP 192.168.63.141.41971 > u.arin.net.domain: 49242% [1au] PTR? 1.4.5.192.inaddr.arpa. (51)
16:11:24.350162 IP u.arin.net.domain > 192.168.63.141.41971: 49242- 0/6/1 (380)
16:11:24.350719 IP 192.168.63.141.4105 > ams.sns-pb.isc.org.domain: 38546% [1au] PTR?
1.4.5.192.in-addr.arpa. (51)
16:11:24.413707 IP ams.sns-pb.isc.org.domain > 192.168.63.141.4105: 38546*- 2/4/13 PTR snspb.isc.org., RRSIG (1472)
16:11:24.415240 IP 192.168.63.141.13054 > ams.sns-pb.isc.org.domain: 52063% [1au] DNSKEY?
4.5.192.in-addr.arpa. (49)
16:11:24.453288 IP 192.168.63.1.48782 > 192.168.63.141.domain: 8138+ PTR? 1.9.0.193.inaddr.arpa. (40)
16:11:24.454104 IP 192.168.63.141.42113 > b.in-addr-servers.arpa.domain: 10746% [1au] PTR?
1.9.0.193.in-addr.arpa. (51)
16:11:24.477378 IP b.in-addr-servers.arpa.domain > 192.168.63.141.42113: 10746- 0/9/1 (463)

Documents pareils